Docker Networking

Docker Networking


Beginner

Q1: What is Docker networking?

Docker networking is the mechanism that allows containers to communicate with each other, with the host, and with external networks.

Q2: Why do containers need networking?

Containers are isolated processes, and without networking they cannot communicate or expose services.

Q3: What is a container network?

A container network is a virtual network that connects containers and controls how traffic flows between them.

Q4: What is the default Docker network?

Docker creates a default bridge network for new containers unless another network is specified.

Q5: What is a bridge network?

A bridge network is an internal virtual network that allows connected containers to communicate with each other.

Q6: What is Docker bridge?

Docker bridge is the default Linux bridge device used by Docker to connect containers on the same host.

Q7: What is a Docker network driver?

A Docker network driver defines how container networking is implemented, such as bridge, host, overlay, macvlan, ipvlan, and none.

Q8: What is the host network mode?

Host network mode makes a container share the host network namespace directly.

Q9: What is the none network mode?

None mode disables networking inside the container entirely.

Q10: What is container-to-container communication?

It is communication between two or more containers over a Docker-managed network.

Q11: What is port publishing?

Port publishing maps a container port to a host port so external clients can reach the container.

Q12: What is port mapping?

Port mapping is another term for port publishing, often written as host:container.

Q13: What is the Docker CLI network command?

The main Docker networking commands include:

  • docker network ls
  • docker network inspect
  • docker network create
  • docker network rm

Q14: What is a Docker container IP address?

Each container on a Docker network can have an IP address assigned to its interface.

Q15: What is Docker network namespace?

A network namespace provides an isolated networking stack for a container, separate from the host.

Q16: What is a veth pair?

A veth pair connects a container network interface to the Docker bridge or another network device.

Q17: What is a Docker bridge interface?

It is the bridge device that acts as a virtual switch for containers on the same host.

Q18: What is a Docker-generated container name?

Docker automatically assigns a name to a container, which can be used for communication in custom networks.

Q19: What is container DNS in Docker?

Docker provides internal DNS resolution so containers can resolve service names on user-defined networks.

Q20: What is service discovery in Docker?

Service discovery is the ability to resolve container names and service names to IP addresses.

Q21: What is docker-compose networking?

Docker Compose creates a default network for the services in a compose project and connects them automatically.

Q22: Why do containers on the same bridge network talk to each other?

Because they are attached to the same virtual bridge and share the same layer-2 segment.

Q23: What is a Docker user-defined network?

A user-defined network is a custom Docker bridge network created by the user for better isolation and DNS.

Q24: What is the difference between default bridge and user-defined bridge?

User-defined bridge networks provide better DNS, automatic service discovery, and better isolation than the default bridge.

Q25: What does Docker use for host networking?

Docker can put a container directly on the host network namespace using –network host.

Q26: What is the purpose of –network none?

It isolates a container completely from all networking.

Q27: What is a container port?

A container port is an application port exposed inside the container, such as 8080 or 5432.

Q28: What is a host port?

A host port is a port on the physical or VM host that forwards traffic to a container.

Q29: What is -p 8080:80?

This Docker command publishes port 80 inside the container to port 8080 on the host.

Q30: What is the difference between publishing and exposing?

Exposing declares a port in the image metadata, while publishing publishes it to the host.

Q31: Why are ports not exposed by default?

Containers are isolated; a port is only reachable externally if explicitly published or attached to an accessible network.

Q32: What is IPAM?

IPAM (IP Address Management) assigns IP addresses within Docker networks.

Q33: What is docker network create?

It creates a new Docker network with a chosen driver and options.

Q34: What is docker network inspect?

It shows details about a network, such as subnets, gateways, and attached containers.

Q35: What is a subnet?

A subnet is a range of IP addresses assigned to a Docker network.

Q36: What is a gateway?

A gateway is the device or IP used as the default route for traffic leaving a network.

Q37: What is a Docker MAC address?

A MAC address identifies a container network interface on the local network segment.

Q38: What is a bridge IP range?

It is the address range used by a Docker bridge network, such as 172.17.0.0/16.

Q39: What is the Docker bridge gateway?

It is the gateway IP assigned to the bridge for traffic leaving the network.

Q40: What is network isolation?

Network isolation restricts traffic between container groups or networks.

Q41: What is an internal Docker network?

An internal Docker network prevents external access to the containers on that network.

Q42: What is a Docker network alias?

A Docker network alias is an alternate name used for a container on a user-defined network.

Q43: What is the difference between a container name and a Docker hostname?

The container name is used by Docker; the hostname is the system hostname inside the container.

Q44: What is Docker DNS resolution for container names?

Docker automatically resolves a container name to its IP on a user-defined network.

Q45: Why use custom networks in Docker?

They improve discovery, isolation, and easier service interaction than relying on random default bridge networking.

Q46: What is container-to-host communication?

It is traffic from a container to the host machine through the bridge or host network.

Q47: What is host-to-container communication?

It is traffic from the host to a published port of a container.

Q48: What is external network access?

It is communication between a container and systems outside the Docker host.

Q49: What is a Docker network driver plugin?

A plugin extends Docker networking with custom implementations beyond built-in drivers.

Q50: What is a Docker network create command example?

Example: docker network create mynet

Q51: What is a worker node in Docker Swarm?

A worker node runs workloads and participates in the Swarm overlay network.

Q52: What is a manager node in Docker Swarm?

A manager node coordinates the services and cluster state in Swarm.

Q53: Why does Swarm need overlay networking?

Because services run on different Docker hosts and need inter-host connectivity.

Q54: What is overlay networking?

Overlay networking creates a virtual network across multiple hosts, often used in Swarm or Kubernetes.

Q55: What is a Docker swarm service?

A swarm service is a container task managed by Docker Swarm and connected via an overlay network.

Q56: What is service discovery in Swarm?

Swarm provides service name resolution to load balance traffic across tasks.

Q57: What is a Docker ingress network?

Ingress in Swarm is an overlay network used to publish ports and route incoming traffic to service tasks.

Q58: What is a service published port?

A published port exposes a service externally across the cluster.

Q59: What is a service task?

A task is one instance of a service running on a node.

Q60: How do containers get IPs in Swarm?

Docker assigns IPs from the overlay network and manages reachability across nodes.

Intermediate

Q61: What are the built-in Docker network drivers?

Common built-in drivers include bridge, host, overlay, macvlan, ipvlan, and none.

Q62: What is the bridge driver?

The bridge driver creates an isolated internal network for containers on a single host.

Q63: What is the overlay driver?

The overlay driver creates a network spanning multiple hosts for swarm or other overlay-based deployments.

Q64: What is the host driver?

The host driver makes the container share the host network directly.

Q65: What is the none driver?

The none driver completely disables networking.

Q66: What is macvlan?

macvlan attaches a container directly to a physical network interface using its own MAC address.

Q67: What is ipvlan?

ipvlan attaches containers to a parent interface while preserving the L2 or L3 semantics of the host network.

Q68: What is the difference between macvlan and ipvlan?

macvlan exposes a distinct MAC per container; ipvlan usually shares the parent MAC while separating L3 identities.

Q69: What is network namespace isolation?

It creates an isolated networking stack so container interfaces and routing are not visible to other containers or the host.

Q70: What is Linux bridge?

Linux bridge is a software switch used by Docker bridge networks to virtualize layer-2 communication.

Q71: What is veth pair usage in Docker?

Docker creates a veth peer for each container, connecting the container namespace to a bridge or network device.

Q72: Why are personal network namespaces needed?

They keep container networking separate from the host and other containers.

Q73: What is DNAT?

DNAT (Destination Network Address Translation) is the mechanism that changes the destination of packets as they pass through Docker port publishing.

Q74: What is SNAT?

SNAT (Source Network Address Translation) changes the source address of packets leaving a network segment, commonly used for outbound connections.

Q75: What is iptables in Docker networking?

Docker uses iptables rules to implement port publishing, NAT, filtering, and communication policies.

Q76: What is nftables?

nftables is a modern replacement for iptables and may be used by newer Docker and Linux networking stacks.

Q77: Why does Docker use iptables?

To enforce NAT, port publishing, and traffic filtering between containers and the host.

Q78: What is container traffic filtering?

Traffic filtering controls which network connections are allowed between containers or between a container and the outside world.

Q79: What is a network policy?

A network policy restricts which containers can communicate with each other, commonly used in orchestrators like Kubernetes.

Q80: What is a Docker network label?

A label is metadata associated with a network used to identify or configure it.

Q81: What is a Docker network driver option?

Driver options are extra parameters used when creating a network, such as subnet, gateway, or internal.

Q82: What is a subnet option?

A subnet option defines the address range assigned to a network.

Q83: What is a gateway option?

A gateway option sets the default gateway for a Docker network.

Q84: What is an internal network option?

An internal network prevents the network from being routed to the outside world.

Q85: What is a Docker embedded DNS?

Docker’s embedded DNS resolves service names inside user-defined networks.

Q86: What is the Docker hostname resolution model?

The hostname of a container is usually the container name; resolvers can resolve it inside a Docker network.

Q87: What is DNS aliasing?

DNS aliasing means the same service can be reached via multiple names.

Q88: Why is user-defined bridge preferred over default bridge?

Because default bridge lacks modern service-discovery and isolation features.

Q89: What is the default bridge network name?

It is usually bridge.

Q90: What is the docker0 bridge?

docker0 is the Linux bridge created by Docker for the default bridge network.

Q91: What is a bridge MTU?

MTU is the maximum transmission unit; Docker networks may use host-default MTU values.

Q92: Why does MTU matter?

Incorrect MTU values can cause fragmentation or connectivity issues, especially with VPNs or overlays.

Q93: What is Docker DNS config?

Docker can inject DNS servers, search domains, and options into containers via the network config.

Q94: What is a network attach?

A network attach is the act of connecting a container to a specific Docker network.

Q95: What is a multi-network container?

A container attached to more than one Docker network can communicate with all attached networks.

Q96: What is a container interface?

A container interface is the virtual network device attached inside the container’s network namespace.

Q97: What is a network namespace share?

Two containers can share a network namespace if they use host mode or a custom setup.

Q98: What is container discovery by name?

Docker networks allow containers to resolve each other by hostname or name.

Q99: What is service interdependence?

Two services may rely on network connectivity to communicate between containers or services.

Q100: What is service mesh vs container network?

A service mesh is an application-level control plane on top of network connectivity; Docker networking is the lower-level connectivity layer.

Q101: What is the relationship between Docker and Linux networking?

Docker relies heavily on Linux networking primitives: bridge devices, veth pairs, iptables, namespaces, and routes.

Q102: What is a routed container network?

A routed network sends traffic as L3 traffic between hosts or networks rather than L2 broadcast domains.

Q103: What is L2 vs L3 in Docker networking?

L2 is link-layer switching; L3 is IP routing between networks.

Q104: What is a Docker overlay network across hosts?

It creates a virtual network spanning multiple Docker hosts and uses VXLAN or similar encapsulation.

Q105: What is VXLAN?

VXLAN is a tunneling protocol often used by Docker overlay and SDN solutions to carry layer-2 traffic over layer-3 networks.

Q106: What is encapsulation in overlay networking?

Encapsulation wraps the original packet in another packet for transport across hosts or networks.

Q107: Why is overlay networking needed?

Because containers on different hosts cannot talk directly without network-level virtualization.

Q108: What is a network controller?

A network controller manages and configures the virtual network in a distributed environment.

Q109: What is a vSwitch?

A virtual switch is a software bridge or switching component that forwards layer-2 traffic in a network.

Q110: What is a virtual network?

A virtual network is an abstract network layer created in software to isolate or connect workloads.

Q111: What is the difference between user-defined bridge and overlay?

A bridge network is local to a host. An overlay network spans across multiple hosts.

Q112: What is a Docker network plugin requirement?

Some drivers require extra packages or agent processes to work across hosts.

Q113: What is a cluster network?

A cluster network connects workloads across multiple nodes in an orchestrated environment.

Q114: What is a swarm overlay network?

A Swarm overlay network connects containers from different nodes in the same cluster.

Q115: What is publish mode in Swarm?

Publish mode defines how a service port is exposed, such as ingress or host mode.

Q116: What is ingress mode?

Ingress mode routes traffic through the Swarm ingress network to reach the correct service task.

Q117: What is host mode in Swarm?

Host mode lets a service bind directly to the host network rather than through ingress.

Q118: What is a local Docker network?

A local network is a Docker network that does not extend across cluster nodes.

Q119: Why can external ports conflict?

Multiple services on the same host cannot bind the same host port unless using special network configurations.

Q120: What is container port conflict?

It happens when two containers attempt to use the same exposed internal port without a conflicting mapping.

Q121: How do you debug network issues in Docker?

Use docker ps, docker inspect, docker logs, ip addr, ip route, ping, and tcpdump.

Q122: What is docker exec?

docker exec allows executing commands inside a running container for network debugging.

Q123: What is docker logs?

docker logs shows application and networking-related logs from a container.

Q124: What is docker inspect network?

It shows details like IP addresses, gateway, network options, and connected containers.

Q125: What is IP forwarding?

IP forwarding allows packets to move between interfaces and networks, usually enabled in Linux for routing.

Q126: Why is ip forwarding important?

Without it, containers may not reach external networks or other network segments.

Q127: What is a NAT rule?

A NAT rule rewrites source or destination addresses or ports for routing and address conservation.

Q128: What is DNAT with Docker?

Docker uses DNAT to map host ports to container ports.

Q129: What is port allocation?

Port allocation is how Docker chooses host ports when a container publishes a port automatically.

Q130: What is random host port?

If no host port is specified, Docker may pick an available random port for publishing.

Q131: What is published port to container port mapping?

It is the mapping of host:container, such as 0.0.0.0:8080->80/tcp.

Q132: What is 0.0.0.0 binding?

Binding to 0.0.0.0 means listening on all interfaces on the host, not just localhost.

Q133: What is localhost binding?

Binding to localhost means the service is only reachable from the local machine, not remote hosts.

Q134: What is a Docker network driver mismatch?

It happens when a container or service tries to connect to a network with a driver that does not support the required topology.

Q135: What is container network namespace cleanup?

Docker removes the container network namespace when the container is deleted.

Q136: What is network stack teardown?

It is the process of removing interfaces, routes, IPAM state, and firewall rules after a container stops.

Q137: What is the effect of restarting Docker?

Restarting Docker can temporarily disrupt container traffic while networks and daemons reinitialize.

Q138: What is a container network state?

It includes IP assignment, veth links, iptables rules, routes, and DNS metadata.

Q139: What is network plugin lifecycle?

It includes driver startup, network creation, attach/detach, and cleanup.

Q140: What is Docker Compose network alias behavior?

Compose automatically creates a network and aliases service names so containers can discover each other by service name.

Q141: What is inter-container DNS?

Inter-container DNS is name resolution between containers on the same Docker network.

Q142: What is DNS search domain?

The DNS search domain adds suffixes to short names so they can be resolved as FQDNs.

Q143: What is user-defined bridge DNS resolution?

User-defined bridge networks provide container name resolution, unlike legacy bridge networks.

Q144: Why do service names matter in Docker networks?

They provide stable names for application clients rather than ephemeral IP addresses.

Q145: What is service discovery in Compose?

Compose service names are automatically resolvable on the project network.

Q146: What is a docker compose project network?

A Compose project network is a Docker network created for a project’s services.

Q147: Why do containers need routing?

Because packets need to know where to go to reach other containers, services, or external networks.

Q148: What is container routing table?

It is the routing table inside the container namespace showing destinations and gateways.

Q149: What is the host routing table?

It is the host OS routing table used to route packets between Docker bridges and other networks.

Q150: What is a local route?

A local route is a route to a directly connected network or interface.

Q151: What is a default route?

A default route sends traffic not matching a specific route to a gateway or network border.

Q152: What is network segmentation?

Network segmentation divides container traffic into separate network boundaries for isolation and security.

Q153: What is a Docker subnet conflict?

It occurs if two networks use overlapping IP ranges, causing routing or connectivity problems.

Q154: What is network overlap?

Network overlap refers to two networks assigning the same or conflicting IP ranges.

Q155: What is docker network prune?

docker network prune removes unused or dangling Docker networks.

Q156: What is a dangling network?

A dangling network is a Docker network not currently attached to any container.

Q157: What is a Docker network driver compatibility issue?

It happens when a chosen driver depends on Linux features or host configuration that is not available.

Q158: What is a custom bridge subnet?

It is a user-defined IP range for a Docker bridge network, configured when the network is created.

Q159: What is bridge isolation?

Bridge isolation restricts traffic between containers attached to the same bridge or between specific networks.

Q160: What is IPv4-only Docker network?

It uses IPv4 addressing only.

Q161: What is IPv6 Docker network?

It uses IPv6 addressing, often requiring additional host configuration and kernel support.

Q162: Why is IPv6 in Docker less common?

Because many deployments still use IPv4 and dual-stack support is more complex.

Q163: What is Docker DNS and NAT interaction?

Docker resolves internal names while iptables handles external translation and forwarding.

Q164: What is container traffic capture?

It is packet capture inside a container or on the host to analyze network behavior.

Q165: What is tcpdump in Docker?

tcpdump can be run inside or outside a container to inspect packets and diagnose networking issues.

Q166: What is health check networking?

Health checks can verify a service is listening on a port before traffic is routed to it.

Q167: Why are health checks important in container networks?

They help ensure backends are actually reachable before routing traffic.

Q168: What is a load balancing layer in Docker?

It may be handled by a reverse proxy, Swarm ingress, or a cloud load balancer.

Q169: What is a sidecar proxy?

A sidecar proxy runs alongside a container and can handle networking, service mesh, or policy enforcement.

Q170: What is a Docker network dependency?

A service may depend on a specific network being created or connected before it starts.

Q171: What is network startup order?

Containers may need the network to be up before they start or before dependencies are reachable.

Q172: What is a container startup race?

A startup race occurs when services try to connect before a dependent container or network is ready.

Q173: What is service readiness?

A service is ready when it can accept traffic and respond successfully to health checks.

Q174: What is a network restart policy?

Docker restart policies control whether containers restart after network-related failures.

Q175: What is a network timeout?

A timeout is the duration before a connection or request fails due to no response.

Q176: Why do containers need stable DNS names?

Stable names allow the app, proxy, and service discovery layer to find backends without hardcoded IPs.

Q177: What is a service registry?

A service registry maintains service addresses and metadata for dynamic discovery.

Q178: What is Docker service discovery in a cluster?

It is the mechanism for locating other services or tasks by name, often via DNS.

Q179: What is ephemeral IP churn?

Ephemeral IP churn is when container IPs change due to recreation, which is why names are better than raw IPs.

Q180: Why should apps avoid hardcoded container IPs?

Because container IPs can change when containers restart or move.

Advanced / Expert

Q181: What is overlay networking under the hood?

Overlay networking often uses VXLAN encapsulation and a distributed control plane to connect hosts.

Q182: What is VXLAN underlay?

The underlay is the physical or routed infrastructure carrying the overlay tunnel traffic.

Q183: What is underlay network in container clusters?

It is the real network fabric that carries container traffic across hosts or cloud environments.

Q184: What is overlay encryption?

Overlay encryption secures traffic between hosts in an overlay network.

Q185: What is network policy enforcement in orchestrators?

It controls allowed traffic patterns between pods or services and is often enforced by CNI plugins.

Q186: What is CNI?

CNI (Container Network Interface) is a specification for configuring container networking in orchestrators like Kubernetes.

Q187: What is Docker CNI integration?

Docker uses its own networking model, but similar concepts appear in CNI-based runtimes like Kubernetes.

Q188: What is eBPF in networking?

eBPF enables programmable packet processing in the Linux kernel for filtering, observability, and custom routing.

Q189: What is network observability in Docker?

It includes metrics, packet capture, logs, DNS resolution traces, and topology inspection.

Q190: What is packet capture in a container?

It is the act of seeing the raw packets flowing through a network namespace for troubleshooting.

Q191: What is a network loop?

A networking loop occurs when packets are continuously forwarded in a cycle, often due to misconfiguration.

Q192: What is a routing leak?

A routing leak occurs when traffic is advertised or forwarded beyond the intended network boundary.

Q193: What is ARP in Docker networking?

ARP resolves layer-2 neighbors for containers on the same network segment.

Q194: Why is ARP relevant in Docker bridge networks?

Because containers on the same Linux bridge need to resolve each other’s MAC addresses.

Q195: What is a multicast network?

A multicast network sends data to a defined group of listeners rather than to every host.

Q196: What is traffic mirroring?

Traffic mirroring duplicates packets to a monitoring or security system for analysis.

Q197: What is a network premium or segmentation policy?

It is a business or security policy that separates traffic by trust level or application boundary.

Q198: What is a firewall rule on Docker host?

It may be implemented via iptables and restrict traffic entering or leaving containers and host ports.

Q199: What is a container network attack surface?

It is the set of networking interfaces, ports, and exposure points available to a container.

Q200: What is the main lesson in Docker networking?

Docker networking is not just about connectivity; it is about isolation, traffic control, name resolution, topology, and secure communication between containers and hosts.